You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When invoking the token API with the password grant type, if the username is incorrect, the error response includes the provided username. From a security perspective, it would be better to improve this error response by removing or sanitizing the username to prevent potential exposure of sensitive information.
Suggested Improvement
Remove the username from the error response
Version
APIM 3.2.0
The text was updated successfully, but these errors were encountered:
Current Limitation
When invoking the token API with the password grant type, if the username is incorrect, the error response includes the provided username. From a security perspective, it would be better to improve this error response by removing or sanitizing the username to prevent potential exposure of sensitive information.
Suggested Improvement
Remove the username from the error response
Version
APIM 3.2.0
The text was updated successfully, but these errors were encountered: